Description
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
Published: 2026-07-10
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw stems from improper input validation in Samsung Pass on Samsung mobile devices. When a local privileged attacker delivers crafted input to versions older than 5.2.10.3, the service writes memory beyond the intended buffer, potentially allowing the attacker to execute arbitrary code and elevate privileges on the device. The description does not indicate consequences beyond this privilege escalation.

Affected Systems

Samsung Pass on Samsung mobile devices. Versions prior to 5.2.10.3 are vulnerable; releases 5.2.10.3 and later contain the fix.

Risk and Exploitability

The CVSS score of 6.8 signifies moderate severity, while an EPSS score below 1% reflects a very low but nonzero likelihood of exploitation. This vulnerability is not listed in CISA KEV. Exploitation requires local privileged access to supply the malicious input; no remote or network attack vector is described.

Generated by OpenCVE AI on July 24, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Pass to version 5.2.10.3 or newer to address the input validation flaw.
  • If Samsung Pass is not required, uninstall or disable the application to eliminate the risk.
  • Limit local privileged accounts that perform actions within Samsung Pass to reduce the potential attack surface.

Generated by OpenCVE AI on July 24, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Samsung Pass Out-of-Bounds Memory Write Leading to Local Privilege Escalation
Weaknesses CWE-119
CWE-416

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Samsung Pass Out-of-Bounds Memory Write Leading to Local Privilege Escalation
Weaknesses CWE-119
CWE-416

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Samsung Pass Local Privilege Escalation via Out-of-Bounds Write
Weaknesses CWE-122
CWE-20
CWE-787

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Samsung Pass Local Privilege Escalation via Out-of-Bounds Write
Weaknesses CWE-122
CWE-20
CWE-787

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out-of-Bounds Write in Samsung Pass
Weaknesses CWE-120

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out-of-Bounds Write in Samsung Pass
Weaknesses CWE-120

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Memory Write in Samsung Pass via Improper Input Validation
Weaknesses CWE-120
CWE-787

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Memory Write in Samsung Pass via Improper Input Validation
Weaknesses CWE-120
CWE-787

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Pass
Vendors & Products Samsung Mobile
Samsung Mobile samsung Pass

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Pass
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T11:30:25.418Z

Reserved: 2025-12-11T01:33:35.821Z

Link: CVE-2026-21057

cve-icon Vulnrichment

Updated: 2026-07-10T11:30:19.464Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T08:30:04Z

Weaknesses

No weakness.